Suspicion-Free Adversarial Attacks on Clustering Algorithms

Suspicion-Free Adversarial Attacks on Clustering Algorithms
复制标题

对聚类算法的无怀疑的对抗性攻击

DOI:
10.1609/aaai.v34i04.5770
复制
发表时间:
2019
期刊:
ArXiv
影响因子:
--
通讯作者:
P. Mohapatra
P. Mohapatra
中科院分区:
--
文献类型:
--
作者:
Anshuman Chhabra;Abhishek Roy;P. Mohapatra

文献摘要

被引文献

相似文献

聚类算法在大量的应用中被使用,并在现代机器学习中扮演着重要的角色--然而,与监督学习不同的是,对聚类算法的对抗性攻击似乎被广泛忽视。在这篇文章中,我们试图通过提出一种针对线性可分簇的聚类模型的黑盒对抗攻击来弥补这一差距。我们的攻击是通过扰动决策边界附近的单个样本来工作的,这会导致多个未扰动样本的错误聚类,称为溢出对抗性样本。我们从理论上证明了K-均值聚类的对抗性样本的存在性。我们的攻击尤其强大,因为(1)我们确保扰动样本不是离群值,因此无法检测,以及(2)攻击者不知道用于聚类的确切度量。我们从理论上证明,在不知道真实度量的情况下,攻击确实可以成功。最后,我们提供了一些数据集和聚类算法的经验结果。就我们所知,这是第一个在不知道确保扰动样本不是异常值的真实度量的情况下生成溢出对手样本的工作,并从理论上证明了上述结论。
Clustering algorithms are used in a large number of applications and play an important role in modern machine learning– yet, adversarial attacks on clustering algorithms seem to be broadly overlooked unlike supervised learning. In this paper, we seek to bridge this gap by proposing a black-box adversarial attack for clustering models for linearly separable clusters. Our attack works by perturbing a single sample close to the decision boundary, which leads to the misclustering of multiple unperturbed samples, named spill-over adversarial samples. We theoretically show the existence of such adversarial samples for the K-Means clustering. Our attack is especially strong as (1) we ensure the perturbed sample is not an outlier, hence not detectable, and (2) the exact metric used for clustering is not known to the attacker. We theoretically justify that the attack can indeed be successful without the knowledge of the true metric. We conclude by providing empirical results on a number of datasets, and clustering algorithms. To the best of our knowledge, this is the first work that generates spill-over adversarial samples without the knowledge of the true metric ensuring that the perturbed sample is not an outlier, and theoretically proves the above.